Skip to content
status: steady

How we work

Scoped engagements, senior engineers, and an end date set at the start. This page is the whole model: access, shapes, timezones, and what happens when we leave.

The course

  1. A first call

    You describe the problem; we say whether we're the right people for it and roughly what it takes. If a consultancy isn't the answer, that call is where you find out.

  2. Read-only review

    Access is granted at the bottom of the ladder and stays there until there's a reason to climb. We map what exists before proposing anything.

  3. The work

    Changes land as pull requests in your repos, reviewed by your engineers. A short written update arrives every week: what moved, what's blocked, what's next.

  4. Handover, then departure

    Documentation and runbooks are written during the work, not assembled at the end. The last session is your team driving while we watch. Then access is revoked.

The access ladder

Letting a consultancy into your cloud accounts is a security decision. We make it an easy one: access starts at the bottom rung and climbs only with a reason, in your audit log the whole way. Read-only is also where the findings come from; we've written up what we look for during an infrastructure review.

01read-onlyAWS: a cross-account IAM role with an external ID. Azure: PIM-scoped Reader, time-bound and logged.
02pull requestsWrite access to production stays with your team. Our changes arrive as PRs your engineers review and merge.
03no standing secretsNo long-lived credentials, no IAM users, no service principals with never-expiring secrets on our side.
04your audit trailOn AWS, every call we make lands in your CloudTrail under the assumed role. On Azure, PIM activations and any changes show up in your logs, and Reader access cannot write, by construction.
05offboardingOn the end date: roles deleted, access revoked, documentation already in your repos. Nothing to hand back.

Three shapes of engagement

Review / audit

fixed scope · fixed price

~2–3 weeks

Written findings ordered by risk, a walkthrough call, and a roadmap your team can run with or without us.

Build / migration

weekly rate · defined end

scoped per engagement

The work itself, landed through your pipelines, with documentation and runbooks written along the way.

Advisory

light retainer · optional

after an engagement

A few hours a month for reviews and questions. Most teams don't need it, and we say so.

Each shape scopes work from the five service areas. No public rate card, but no mystery either: ask and we state the numbers plainly, before any commitment. We don't take percentage-of-savings deals, and we don't sell open-ended retainers. The full pricing logic, including why the numbers land well, is on the Pricing page.

Working from Kerala, India · 10°N 76°E

We work from Kerala, India, on IST, and we're upfront about the mechanics. IST overlaps the European workday deep into their afternoon. For US teams, our evenings meet East Coast mornings, enough for standups and handoffs. West Coast overlap is thinner, and we say so before you sign anything. Most of the work is asynchronous by design: pull requests and written updates read well in any timezone.

The weekly update

// illustrative: the format, not a client's data

week 3 of 6 · cost review

shipped: tagging policy enforced in CI; dev scheduler live

found: gp2→gp3 migration unfinished from 2024, ~40 volumes

blocked: need an owner for the shared staging cluster

next: commitment coverage review, then the findings call

Questions we get

How is pricing structured?
Fixed-scope for reviews and audits, a weekly rate for build work; the three shapes above carry the details. No public rate card, but numbers get stated plainly when you ask, before any commitment.
Is there a minimum engagement?
Yes. We don't do hourly odd jobs. The smallest engagement is a fixed-scope review, which runs roughly two weeks. Anything shorter tends to produce advice without enough context to be worth acting on. If your problem genuinely fits in an afternoon, a call may cover it, and we'll tell you so rather than dress it up as a project.
Do you work in our timezone?
Yes, within stated limits. We're on IST: that overlaps the European workday deep into their afternoon, and our evenings meet US East Coast mornings. West Coast overlap is thinner, and we say that before you sign anything. Pull requests and written updates carry the rest asynchronously.
Who owns the code and the accounts?
You do, always. Everything runs in your cloud accounts and your repositories; our work arrives as pull requests that you review and merge. Access starts read-only (a cross-account role on AWS, PIM-scoped Reader on Azure) and we hold no long-lived credentials. When the engagement ends there is nothing of yours sitting on our side to hand back.
Do you sign NDAs?
Yes, routinely. Send yours over and we'll review it; standard mutual NDAs get signed quickly, and we can provide one if you'd rather use ours. We're comfortable with confidentiality being a condition of starting, not a negotiation. If your legal team needs specific data-handling terms in the services agreement as well, that's a normal conversation.
What happens when you leave: what does offboarding look like?
Offboarding is deliberately unremarkable. Access is revoked on the last day; since we work through short-lived roles rather than long-lived credentials, there's little to revoke. You keep the documentation and runbooks we wrote along the way, not a bundle assembled at the end. Every engagement is scoped with a defined end, so that date is known from the start.
What if you think we do not need you?
We tell you, and point you at what to do instead. Sometimes that's a managed service, sometimes a config change your own team can make in a day, sometimes just a document to read. Billing a retainer to supervise a problem that doesn't exist is bad business on a long enough horizon. Scoping calls are where this gets said, before money moves.

Scope the first call.

A short email about your setup and what's not working is the best start. We'll say plainly whether we can help, and what it would take.

hello@farzanfa.com · +91 88918 87223 · Kerala, India · working worldwide · reply within one business day